Back
CVE-2001-1202
Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.
Published: Dec 28, 2001
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| delegate | delegate | 7.7.0 |
| delegate | delegate | 7.7.1 |
| delegate | delegate | 7.8.0 |
| delegate | delegate | 7.8.1 |
GitHub Security Advisory GHSA-7hgq-qg3c-85g8
Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands...
References (6)
- http://marc.info/?l=bugtraq&m=100956050432351&w=2
- http://www.iss.net/security_center/static/7745.php Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3749
- http://marc.info/?l=bugtraq&m=100956050432351&w=2
- http://www.iss.net/security_center/static/7745.php Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3749
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
6.67%
Top 7% most likely to be exploited
Threat Score
32 / 100
Data Sources
NVD
EPSS
GitHub